Description

WordPress Plugin User Registration & User Profile-Profile Builder is prone to a security bypass vulnerability. Successfully exploiting this issue may allow an attacker to gain access to the change password functionality and change the password of an arbitrary user, resulting in accessing user account. WordPress Plugin User Registration & User Profile-Profile Builder version 1.1.24 is vulnerable; prior versions may also be affected.

Remediation

Update to plugin version 1.1.26 or latest

References

Related Vulnerabilities